• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

This is one mean virus!

typhoon43

2[H]4U
Joined
Apr 5, 2001
Messages
3,930
Wow, working on a friend's machine and it's a nasty one. It's changed all the file associations so that all the icons appear as .lnk
You can't run cmd.exe, regedit, or ANY program for the matter
Error is "Windows cannot open this file cmd.exe" and asks if you want to search on the web or choose a program to open it.

I can get the box online by opening My Computer and typing google in the address bar. After 20 popups are done :D I can surf.

All the things I have found tell you to rename regedit.exe to regedit.scr or try command.com instead of cmd, but I keep getting the same error.

What's scarier is I tried to do a repair from the XP disc and after it asked for my CD key and started installing devices I got the same popup saying "Windows cannot open this file: regsvr32.exe

Update: I CAN boot from the CD and enter "Safe mode with command prompt" Any idea what files I need to copy off the disc to get it up so I can run a real Virus scan (Trend Housecall found 39 Viruses but didn't seem to clean them).

This one has me flustered.

Remember, all I can do is copy files from disc to HD. I can't RUN anything.

Anyone else seen this yet?
 
reformat.....

and also try booting up to safe mode with networking, and then go online and do a trendmicro scan and panda scan

if you have a process viewer you can look through your modules and find if any (which i am sure you will find some) .dll files injected themselves into something.
 
As I stated originally, I have done a Trend Online scan, and the Panda for some reason SCANNED, but never gave me a choice to clean. It was just like "hey, here's all the bad stuff on your PC..gotta go!" :D I coppied ntdll.dll over last night, I'll try nt32.dll tonight and see what happens.

Formatting is a LAST ditch effort. Lots of personal photos/etc. Sure I could take the drive out, copy over the files, and reformat, but where's the challenge in that? :p
 
Ranma I believe it's Pretty Park but there was another as well. I think it was called SWEM.
I'll post more tonight when I get over there. Definitely the nastiest thing I've ever had the pleasure of dealing with.

Do normal .exe's associate with shell.dll or nt32dll.dll?

I won't be beaten! But I have to admit not being able to double click even a .reg or .bat file makes it tough (since every fix on the Internet seems to mention doing it)

EDIT:
Here is most widely accepted fix, but since I can't execute .reg files I have no clue how I can get it to install:
Code:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\.exe]
@="exefile"
"Content Type"="application/x-msdownload"

[HKEY_CLASSES_ROOT\.exe\PersistentHandler]
@="{098f2470-bae0-11cd-b579-08002b30bfeb}"

[HKEY_CLASSES_ROOT\exefile]
@="Application"
"EditFlags"=hex:38,07,00,00
"TileInfo"="prop:FileDescription;Company;FileVersion"
"InfoTip"="prop:FileDescription;Company;FileVersion;Create;Size"

[HKEY_CLASSES_ROOT\exefile\DefaultIcon]
@="%1"

[HKEY_CLASSES_ROOT\exefile\shell]

[HKEY_CLASSES_ROOT\exefile\shell\open]
"EditFlags"=hex:00,00,00,00

[HKEY_CLASSES_ROOT\exefile\shell\open\command]
@="\"%1\" %*"

[HKEY_CLASSES_ROOT\exefile\shell\runas]

[HKEY_CLASSES_ROOT\exefile\shell\runas\command]
@="\"%1\" %*"

[HKEY_CLASSES_ROOT\exefile\shellex]

[HKEY_CLASSES_ROOT\exefile\shellex\DropHandler]
@="{86C86720-42A0-1069-A2E8-08002B30309D}"

[HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers]

[HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers\PEAnalyser]
@="{09A63660-16F9-11d0-B1DF-004F56001CA7}"

[HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers\PifProps]
@="{86F19A00-42A0-1069-A2E9-08002B30309D}"

[HKEY_CLASSES_ROOT\exefile\shellex\PropertySheetHandlers\ShimLayer Property Page]
@="{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"
 
Wipe and reload. You will spend less time on it than trying to fix it.

Unless this is a challenge, in which case I can full appreciate that.
 
slave the drive to a clean computer and run your antivirus stuffs that way. Wont fix the bad associations, though, probably.
 
XOR != OR said:
Wipe and reload. You will spend less time on it than trying to fix it.

Unless this is a challenge, in which case I can full appreciate that.

Oh yeah baby, this is most definitely a CHALLENGE.

BRING IT ON!!!
joe_tn.jpg
 
I just wiped a PC here at work with a similar problem. Any program you'd try to run would generate an error and close. I did have fun playing a little game on one of the popups though! :cool:
 
Did you try running regedit.com instead of regedit.exe? I had a virus that changed the extension probably a year ago or so..and thats what i had to do. If regedit.com wont open the registry can you search for regedit.exe and try to rename it to regedit.com? That might work. Also search for Files32.vxd and maybe prettypark.exe . If found delete them. Question.....did he just get this from Limewire or something?? My brothers neighbor just got something similar sounding lastweek and he just reformatted. I really would have liked to seen his pc before he did that though.
 
I like challenges myself. A format is too easy. Plus you gotta restore all the data.
On something like that I would remove the drive and hook it up to a pc running NOD32 and see if it cleans it up. Plus run all your favorite anti spyware apps as well.
 
Yeah, looks like everytime you run an .exe your gonna reinfect yourself.


http://nu2.nu/pebuilder/

Make that on a clean machine. Boot it. Make the reg changes to the offline hive. Once you get the ASEP points gone, boot into the machine, and then run a full antivirus scan.

Pretty Park wasn't nasty, unless you got a nasty variant off it. (In fact it wouldn't do anything on W2K since it used 9x ASEP points.)

As to your question I don't understand it. EXE's don't require any dll's unless their writers required them.
 
With virus's like this it might not be a bad idea to create a small Windows 2000 partition to dual boot. At least you would be able to get in and run a scan.
 
Ranma,
thx, I'll try to clean the reg manually from a boot. They DO have Limewire installed. I could have sworn the newest LW didn't have any malware. Hmm..
 
typhoon43 said:
They DO have Limewire installed. I could have sworn the newest LW didn't have any malware. Hmm..


No, I wasnt meaning Limewire had malware installed. What I was reffering to is in the last month or so Ive had some friends getting alot of bad files from there. I just called my brothers neighbor and he said what infected his pc was W32.Alcra.B which changed some .exe extensions to .com. If you look here...Symantec it gives you some info on what he had. Look in C:\Windows\System32 and see if some of these are listed...

cmd.com
netstat.com
ping.com
regedit.com
taskkill.com
tasklist.com
tracert.com

If so, what you have might be that or a variant. Just make them aware that there has been some virus's being spread on Limewire.
 
just a question -- does "Remote Assitance" still work on that computer? can you run stuff through that from anotehr computer?

or can you VNC in and do stuff?

or , can you tunnel into (SSH i think is hte name of the protocol, i just didn't want to say it because i was afraid of sounding stupid) a linux distro like Knoppix Live and then run stuff to scan the Windows partitions? (*nix can read NTFS fine, but can't write to it without screwing stuff up)

OR, can you map the infected HDD to a network and run scans remotely from your computer on his?

EDIT: The last one is the suggestion i'd pin my hopes on -- do a Spybot S&D and an Adaware scan, and an AVG FreeEdition. Or if you have access to real firepower, NOD32 or Kapersky :D
 
Back
Top